Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the…
Info
Summary
Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never offered causes the client to complete the handshake without validating the server's certificate, so ssl:connect returns {ok, Socket} against a peer holding no certificate, no private key and no prior session. tls_client_connection_1_3:handle_server_hello/2 passes …
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://cna.erlef.org/cves/CVE-2026-89422.html
- https://github.com/erlang/otp/commit/21b8a1b0ad0adf200682b3854bc50114ab2b8c62
- https://github.com/erlang/otp/commit/98c66c858113949c4262d26cd7d426c4b09d2b35
- https://github.com/erlang/otp/commit/afec5156361bb50d3607c7c1a453c19b9149b324
- https://github.com/erlang/otp/commit/fd1d9d07fc92ec0d59f96dfb66182195882bb7dd
- https://github.com/erlang/otp/security/advisories/GHSA-rgxr-4g4w-j875
- https://osv.dev/vulnerability/EEF-CVE-2026-89422
- https://www.erlang.org/doc/system/versions.html#order-of-versions
Timeline
- nvd_ingest NVD